Discover all the security risks and exploits that can threaten
i OS-based mobile devices
i OS is Apple’s mobile operating system for the i Phone and i Pad.
With the introduction of i OS5, many security issues have come to
light. This book explains and discusses them all. The award-winning
author team, experts in Mac and i OS security, examines the
vulnerabilities and the internals of i OS to show how attacks can be
mitigated. The book explains how the operating system works, its
overall security architecture, and the security risks associated
with it, as well as exploits, rootkits, and other payloads
developed for it.
* Covers i OS security architecture, vulnerability hunting,
exploit writing, and how i OS jailbreaks work
* Explores i OS enterprise and encryption, code signing and memory
protection, sandboxing, i Phone fuzzing, exploitation, ROP payloads,
and baseband attacks
* Also examines kernel debugging and exploitation
* Companion website includes source code and tools to facilitate
your efforts
i OS Hacker’s Handbook arms you with the tools needed to
identify, understand, and foil i OS attacks.
Зміст
Introduction xv
Chapter 1 i OS Security Basics 1
Chapter 2 i OS in the Enterprise 15
Chapter 3 Encryption 47
Chapter 4 Code Signing and Memory Protections 69
Chapter 5 Sandboxing 107
Chapter 6 Fuzzing i OS Applications 139
Chapter 7 Exploitation 185
Chapter 8 Return-Oriented Programming 219
Chapter 9 Kernel Debugging and Exploitation 249
Chapter 10 Jailbreaking 297
Chapter 11 Baseband Attacks 327
Appendix References 365
Index 369
Про автора
Charlie Miller is Principal Research Consultant at Accuvant Labs and a four-time Can Sec West Pwn2Own winner.
Dionysus Blazakis is an expert on i OS and OS X sandbox security mechanisms.
Dino Dai Zovi is coauthor of The Mac Hacker’s Handbook and a popular conference speaker.
Stefan Esser is a PHP security expert and leading researcher of i OS security topics.
Vincenzo Iozzo is an independent security researcher focused on Mac OS X and smartphones.
Ralf-Philipp Weinmann holds a Ph D in cryptography and has an extensive security background.